Open the admission file cupboard in any school in India and you will find the same thing: photocopies of Aadhaar cards, birth certificates, caste and income certificates, medical notes about a child's asthma, a father's salary slip, and passport photographs of children going back a decade. Nobody in the building thinks of that cupboard as a database. It is.
The Digital Personal Data Protection Act, 2023 gives that cupboard, and the spreadsheets and WhatsApp groups that grew around it, a legal shape. Schools become data fiduciaries — the entity deciding why and how personal data gets processed. Students and their parents become data principals. And because almost everyone in the building is under eighteen, a school lands inside the strictest part of the Act rather than the general part.
One clarification decides how much of this applies to you. The Act governs personal data in digital form, including data collected on paper and later digitised. The moment your office types those admission forms into a spreadsheet — and every school does, for the annual return if nothing else — the cupboard has become digital data with duties attached. Rules and compliance timelines under the Act are being phased in, so confirm the current position rather than assuming urgency or amnesty. The work below is worth doing either way.
What a school actually holds, listed honestly
Before consent, before notices, before anything: write down what you have. Most principals are surprised by their own list, because it accumulated one form at a time over fifteen years.
- Identity documents for children and parents — birth certificates, Aadhaar copies, sometimes ration cards
- Health information: allergies, chronic conditions, medication, disability certificates, the nurse's register
- Financial information: fee ledgers, concession applications, income certificates, bank details for refunds
- Academic records: marks, ranks, remedial notes, disciplinary entries, counsellor observations
- Contact data: parents' phone numbers, addresses, workplace details, emergency contacts
- Photographs and video from annual days, sports meets, field trips and CCTV
- Transport data — which child boards which bus, at which stop, at what time
- Enquiry data from families who visited, filled a form, and never joined
Two entries are handled far more casually than they deserve. Health information about a child should not be sitting in a shared staffroom folder. And enquiries from families who never enrolled are data you have no ongoing reason to hold, which makes them pure liability.
Children's data and verifiable parental consent
Under the Act a child is anyone below eighteen, and for a child the consent that matters is the parent's or lawful guardian's — and it has to be verifiable. That word is the whole obligation. A tick in a box on a form that anyone in the family could have filled in is not obviously verifiable consent; a signed admission consent taken from a guardian whose identity the school has actually established, recorded against the child, is much closer to the mark.
The Act also draws two bright lines for children specifically. A fiduciary must not process a child's data in a way likely to have a detrimental effect on their well-being. And it must not undertake tracking or behavioural monitoring of children, or direct advertising at them. That second line lands less on schools than on the app ecosystem schools invite in — the free learning platform, the quiz tool, the gamified reading app somebody signed the whole class up for. When a school hands a vendor a class list, the school made the introduction.
Consent also has to follow a notice a parent can actually read: what data, for what purpose, how to withdraw, how to complain. The Act contemplates that notice being available in English or any of the languages in the Eighth Schedule to the Constitution. For most Indian schools that is not a technicality — it is the difference between real consent and a signature on an English form nobody understood. If your parents speak Marathi or Gujarati, that is the language the notice belongs in.
Note also that the Act allows certain duties to be relaxed for notified classes of fiduciaries and purposes. Whether, and how far, that reaches educational institutions is a question of the rules as they stand when you read this. Check it; do not assume it in either direction.
The drawer of Aadhaar photocopies, and why it should be empty
The photocopy habit is the single easiest thing to fix and the one schools defend hardest. Somebody once said to keep a copy on file, and now every admission demands one.
Ask the honest question: what does the school do with that photocopy after admission day? Almost always, nothing. It was used once to check a date of birth, then sat in a file for eleven years being a risk. You gained a verification you could have done by sight, and kept a document that would matter enormously if the cupboard were ever emptied by the wrong person.
The better pattern is to verify at the counter and store the minimum that proves you did. Sight the document, record that it was sighted and by whom, and keep only an identifier fragment — the last four digits — where a reference number is genuinely needed. That is enough to match a record and useless to anyone who steals it. Where a specific government scheme genuinely requires the full number, that is a defined purpose with its own rules, and it should be handled as its own narrow exception rather than as the school's default demand from every family.
Purpose limits: admissions data used for admissions
Consent under the Act is tied to a stated purpose, and the data collected is meant to be limited to what that purpose needs. Schools break this constantly, always with good intentions.
The father's mobile number was collected so the school could reach him about his daughter. It ends up on a list used to promote the school's new summer camp. The income certificate was collected for a fee concession and gets consulted when deciding who to press for a donation towards the new building. The enquiry list from three admission seasons ago becomes the calling list for this season's intake.
None of these feel like violations inside the school, because everyone means well and the data is right there. That is exactly why the discipline has to be written down: each collection has a purpose, and a new purpose needs a new consent. One sentence enforces it — if you are about to use a parent's contact detail for something other than their own child, stop and ask what they agreed to.
Who inside the school can see what
The most likely source of a data problem in a school is not a hacker. It is the shared login, the folder on the office desktop that everyone can open, and the spreadsheet named final_students_list_v4 that has been forwarded to nine people over two years and now lives on a former employee's laptop.
Set the internal boundary deliberately. A class teacher needs her own students' academic and attendance records and their guardians' contacts. She does not need the whole school's fee ledger. Accounts needs the fee position, not counsellor notes. The nurse needs medical information; the front desk does not.
Then apply the same question to anything you buy. A school's records should sit in isolated per-school storage rather than pooled with other institutions, and a vendor should be able to demonstrate that separation rather than assert it. Ask who at the vendor can read your data, under what circumstances, and what is logged when they do.
Photographs, WhatsApp groups and the consent nobody took
The annual day photographs go up on the school's social media the same night. Nobody asked. The reasoning is that the parents were present and clearly delighted, which is true and is not consent to publish a named child's photograph to the public internet permanently.
Publication consent is a separate purpose from admission, and it should be a separate, specific, revocable option — one that a family can decline without their child being visibly excluded from the photograph on the stage. Some families have very good private reasons for saying no, and a school that makes saying no awkward has not really offered a choice.
The class WhatsApp group is the same problem with less glamour. Adding forty parents to a group publishes forty phone numbers to thirty-nine strangers, permanently, with no way to take it back. A broadcast where recipients cannot see each other does the same job without turning your parent directory into a public document. And the teacher's personal phone, full of children's photographs from the science-centre trip, is a school data store that goes home every evening and gets sold second-hand in two years.
Retention: the alumni records from 2009
The Act's position on retention is that data should not be kept once the purpose it was collected for has been served, unless a law requires you to keep it. Schools have both cases sitting in the same cupboard and treat them identically.
Some school records genuinely must be kept for long periods under board and state regulations — admission registers, transfer certificates, examination records. That is statutory retention, not hoarding. Hoarding is the enquiry forms from families who never joined, scanned Aadhaar copies of children who left in 2011, and backups of a system you stopped using four years ago.
Write a one-page retention rule: what is kept permanently because a regulation says so, what is kept for a defined number of years, and what is deleted at the end of each academic session. Then actually run the deletion once a year, on a date, with someone's name against it. A retention policy nobody executes is worse than none, because it documents that you knew.
Vendors and apps as processors of your students' data
Count the third parties holding your students' data right now. The bus-tracking app. The exam or report-card tool. The photographer who has ten years of school events on a hard disk. The bulk-SMS provider. The uniform vendor who was given a list with sizes and phone numbers. The ERP.
Under the Act a processor may be engaged only under a valid contract, and the fiduciary — the school — remains answerable for what happens to the data. You cannot outsource the responsibility along with the file. Reasonable security safeguards are the school's duty, and where a personal data breach occurs, notification obligations follow, to the Board and to the people affected.
- Is there a written contract, and does it say what the vendor may and may not do with the data?
- Where is it stored, who at the vendor can access it, and is that access logged?
- Is any of it used for the vendor's own analytics, product training or advertising — a question that matters doubly because these are children?
- What happens on exit: do you get a full export, and is their copy deleted on a defined timeline?
- If they have a breach, how fast do they tell you, and in what form?
A school cannot outsource responsibility for a child's data. It can only outsource the storage — and it still answers for what happens there.
A practical first pass for a single-campus school
None of this needs a compliance department. A single-campus school can make real progress in one term with a handful of decisions.
- Name one person as the owner. A vice-principal or the administrative head. Every query, complaint and deletion request goes to them.
- Write the inventory: what you hold, where it physically or digitally sits, and why.
- Cut the collection. Delete the fields on the admission form that nobody has used in five years, and stop demanding photocopies you do not need.
- Rewrite the admission consent as a plain-language notice in the language your parents actually read, with publication of photographs as its own separate and revocable choice.
- Fix internal access: no shared logins, records visible by role, and a rule that student lists never leave the system as loose spreadsheets.
- Run a one-time purge of what you should not still be holding, then set an annual date to repeat it.
- Get a contract in place with every vendor that touches student data, and drop the ones that will not sign one.
- Write half a page on what the school does if data is lost or exposed, including who is told and how quickly.
The software you run should make the easy parts automatic rather than aspirational. Bulk onboarding that validates each row instead of importing rubbish. Storage isolated per school. Only the last four digits kept where a full Aadhaar number was once demanded. Fee, attendance and academic records in one system, instead of nine spreadsheets on six laptops nobody can find, delete or account for.
Nothing here is exotic and nothing here is new in spirit. Parents have always trusted schools with the most sensitive information they have about the people they care about most. The Act simply writes down what that trust obliges — and children's data is where it obliges the most.